# Auditbeat File Integrity (Windows OS) Doesn't Capture WHO Changed Files?

**URL:** <https://discuss.elastic.co/t/auditbeat-file-integrity-windows-os-doesnt-capture-who-changed-files/265518>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [February 25, 2021, 4:55pm UTC](https://discuss.elastic.co/t/auditbeat-file-integrity-windows-os-doesnt-capture-who-changed-files/265518 "2021-02-25T16:55:38Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![efaile](https://avatars.discourse-cdn.com/v4/letter/e/f0a364/32.png) [@efaile](https://discuss.elastic.co/u/efaile)\
**Post date:** [February 25, 2021, 4:55pm UTC](https://discuss.elastic.co/t/auditbeat-file-integrity-windows-os-doesnt-capture-who-changed-files/265518/1 "2021-02-25T16:55:38Z")

</div>

We need a File Integrity Monitoring solution for Windows OS's - on the server we use as file servers . To further explain "file servers" - not to monitor remotely across shares which is not supported - but directly on the server.

Got the auditbeat 7.10 file integrity module running and reporting into the Elastic/kibana - and was then shocked that although changes to files are being reported (yay) - the person who DID the change is NOT reporting (bad).

I saw a post from 2019 reporting the same issue and am posting again in hopes that there has been improvement in this area (to make FIM meaningful to most commercial users trying to move workloads into Elastic and turn down other software).

Anything new or planned in the roadmap for FIM?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [February 25, 2021, 10:19pm UTC](https://discuss.elastic.co/t/auditbeat-file-integrity-windows-os-doesnt-capture-who-changed-files/265518/2 "2021-02-25T22:19:03Z")

</div>

The [APIs that Auditbeat FIM uses](https://www.elastic.co/guide/en/beats/auditbeat/current/auditbeat-module-file_integrity.html#_how_it_works_2) to collect this info do not report any user info. You'd have to use the OS'es auditing feature to get that data or use software that has lower level hooks.

[Elastic Endpoint Security](https://www.elastic.co/endpoint-security/) does report this info in its file events. IIRC it uses a kernel driver to be able to get this low level filesystem data.

---

<div class="post-metadata">

**Author:** ![efaile](https://avatars.discourse-cdn.com/v4/letter/e/f0a364/32.png) [@efaile](https://discuss.elastic.co/u/efaile)\
**Post date:** [February 25, 2021, 10:32pm UTC](https://discuss.elastic.co/t/auditbeat-file-integrity-windows-os-doesnt-capture-who-changed-files/265518/3 "2021-02-25T22:32:01Z")

</div>

Thanks Andrew. I'm testing on a brand new file server, so auditing may not be enabled. Is that to say that when audit features of the OS are enabled that Elastic/auditbeat would collect/report those?

I will test this through - posting the follow up question to help others as much as myself as the topic is not thoroughly covered anywhere I have found (yet)!

Appreciate the prompt response - thanks!

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [February 26, 2021, 4:30am UTC](https://discuss.elastic.co/t/auditbeat-file-integrity-windows-os-doesnt-capture-who-changed-files/265518/4 "2021-02-26T04:30:50Z")

</div>

> [@efaile](#):
>
> Is that to say that when audit features of the OS are enabled that Elastic/auditbeat would collect/report those?

Windows auditing events are written to the Security event log (Winlogbeat could read them).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 26, 2021, 6:31am UTC](https://discuss.elastic.co/t/auditbeat-file-integrity-windows-os-doesnt-capture-who-changed-files/265518/5 "2021-03-26T06:31:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
